Generating an Attack Plan

Every scientific test has two things in common:

  • Strict measurable goals

  • A detailed process plan

A penetration test is a scientific test for security holes on your network. You, as a tester, attempt to exploit every known hole in your defenses, test how your defenses hold, test whether they catch the attack, and get knowledge of what to look for in a real attack by studying your pitched attacks.

There are two basic philosophies behind penetration testing. The first philosophy states that the test should be as static as possible. Many commercial vulnerability analysis tools are like this. They follow a set step-by-step process in gathering information and making scripted attacks to discern vulnerabilities. This can quantitatively ...

Get Microsoft® Windows® 2000 Security Handbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.